Privacy Policy
Last updated:
WonderFunnel B.V. (“WonderFunnel”, “we”, “us”, or “our”) is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard information about you when you use our platform and website.
We process personal data as a data controller under the General Data Protection Regulation (GDPR) and applicable Dutch data protection law.
1. Data Controller
WonderFunnel B.V.
Registered in the Netherlands
Contact: privacy@wonderfunnel.io
2. What Data We Collect
Account and contact data
- Name, work email address, and job title
- Company name and size
- Billing information (processed by our payment provider)
Usage data
- Pages visited, features used, and time spent in the platform
- IP address and browser/device type (anonymised where possible)
- Referral source and UTM parameters
Candidate data
When you upload CVs or candidate information to WonderFunnel, you act as a data controller for that candidate data and we act as your data processor. Our Data Processing Agreement (DPA) governs this processing.
3. Legal Basis for Processing
- Contract performance — processing necessary to provide the service you have subscribed to (Art. 6(1)(b) GDPR)
- Legitimate interests — analytics, security monitoring, and product improvement (Art. 6(1)(f) GDPR)
- Consent — optional analytics cookies and marketing communications (Art. 6(1)(a) GDPR)
- Legal obligation — invoicing and tax records (Art. 6(1)(c) GDPR)
4. How We Use Your Data
- To provide, maintain, and improve the WonderFunnel platform
- To send transactional emails (account setup, billing, security)
- To send product updates and marketing (with your consent, opt-out any time)
- To analyse usage patterns and improve user experience
- To comply with legal obligations
5. Third-Party Processors
We share data only with processors bound by data processing agreements:
- Google Analytics 4 — anonymised usage analytics (EU data residency)
- Vercel — website hosting and edge delivery
- Stripe — payment processing
- Postmark — transactional email delivery
We do not sell your personal data to third parties.
6. Data Retention
- Account data: retained for the duration of your subscription plus 2 years
- Usage/analytics data: 26 months (Google Analytics default)
- Billing records: 7 years (Dutch tax law)
7. Your Rights
Under GDPR you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data (“right to be forgotten”)
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interests
- Restriction — request that we limit processing in certain circumstances
- Withdraw consent — withdraw consent at any time where processing is consent-based
To exercise any right, contact us at privacy@wonderfunnel.io. We will respond within 30 days. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
8. Security
We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS 1.2+), encryption at rest, access controls, and regular security reviews.
9. Changes to This Policy
We may update this policy periodically. We will notify you of material changes via email or an in-product notice at least 30 days before they take effect. The “last updated” date at the top of this page reflects the most recent revision.